Prosecution Insights
Last updated: October 02, 2026
Application No. 18/846,865

REPORTING HASHED EXPECTED CHANNEL MEASUREMENTS

Non-Final OA §102§103
Filed
Sep 13, 2024
Priority
Apr 06, 2022 — GR 20220100302 +1 more
Examiner
GELIN, JEAN ALLAND
Art Unit
2643
Tech Center
2600 — Communications
Assignee
Qualcomm Incorporated
OA Round
1 (Non-Final)
88%
Grant Probability
Favorable
1-2
OA Rounds
3m
Est. Remaining
93%
With Interview

Examiner Intelligence

Grants 88% — above average
88%
Career Allowance Rate
1127 granted / 1273 resolved
+26.5% vs TC avg
Minimal +4% lift
Without
With
+4.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 3m
Avg Prosecution
33 currently pending
Career history
1298
Total Applications
across all art units

Statute-Specific Performance

§101
5.1%
-34.9% vs TC avg
§103
45.1%
+5.1% vs TC avg
§102
27.3%
-12.7% vs TC avg
§112
3.1%
-36.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1273 resolved cases

Office Action

§102 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Objections Claims 28-29 are objected to because of the following informalities: they appear to be incomplete. Appropriate correction is required. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 20, 28-29, and 47 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Wang et al. (US 2020/0322805). Regarding claim 20, Wang discloses all the features of broadest: A method of wireless communication performed by a network node [cf. figure 6: "UE 110" and paragraph 0074: FIG. 6 illustrates details of example data transactions between the base station 120, the UE 110 for base station location authentication." and paragraph 0010: " FIG. 1 illustrates an example wireless network environment subject to a cellular-network spoofing attack."] comprising: (a) receiving, from a location server [cf. figure 6: " base station 120", sending "encrypted Positioning Reference Signal (PRS)" in message "608" to "UE 110" and paragraph 0080: II the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610, and paragraph 0079: " a message authentication code a digital signature, employ a one-way function (e.g., a cryptographic hash function)"] , a first set of one or more hashed values, [cf. paragraph 0074: II At 606, the base station 120 encrypts a positioning reference signal 160 using the security key 321" paragraph 0080: II the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610, and paragraph 0079: a message authentication code a digital signature, employ a one-way function (e.g., a cryptographic hash function)"] wherein the first set of one or more hashed values is based on one or more hashing operations applied to one or more expected measurement values, wherein the one or more expected measurement values correspond to expected measurements of one or more positioning reference signal (PRS) resources , [cf. paragraph 0074: At 606, the base station 120 encrypts a positioning reference signal 160 using the security key 321" and paragraph 0080: the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610, and paragraph 0079: " a message authentication code a digital signature, employ a one-way function (e.g., a cryptographic hash function)"] of one or more transmission-reception points (TRPs) [cf. figure 6; "Base Station 120" in Wang is the same as the TRP(s) defined in the present application paragraph 0033 as follow: "where the term "base station" refers to a single physical TRP"] measured by a user equipment (UE) during a positioning session [cf. figure 6. relates to a positioning (location determination) session see "step 620" and paragraph 0084: At 620, the UE 110 determines its cellular-network location"] ; and (b) using the first set of one or more hashed values for PRS attack detection [cf. paragraphs 0079-0080: " the UE 110 executes an authentication procedure to determine that the base station 120 is authenticated by the base-station-location server 264. The authentication procedure can be performed in a variety of different ways based on the cryptography employed by the base station at 602, such as those that verify a message authentication code, verify a digital signature, employ a one-way function (e.g., a cryptographic hash function) the UE 110 verifies the digital signal or the MAC using the security key 322." and paragraph 0018: The authenticated base stations use the security keys to generate encrypted positioning reference signals that protect information transmitted to the UE and enable the UE to verify that the base stations are authenticated In this manner, the UE is protected from spoofing attacks that can otherwise cause the UE to provide false or misleading location information to the user.", note that if the digital signature/MAC can not be verified by UE 110 implicitly means that the base station is not authenticated and that it is sending malicious PRS, meaning performing a PRS attack see also paragraph 0043: " the UE 110 determines that the base station 120 is not authenticated and therefore does not use a positioning reference signal 160 transmitted by the unauthenticated base station to determine a cellular- network location."] Regarding claims 28-29, Wang discloses all the features of broadest: a network node, comprising: a memory; at least one transceiver (typical feature of communication device); and at least one processor communicatively coupled to the memory and the at least one transceiver (typical feature of communication device), the at least one processor configured to: receive, from a location server [cf. figure 6: " base station 120", sending "encrypted Positioning Reference Signal (PRS)" in message "608" to "UE 110" and paragraph 0080: II the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610, and paragraph 0079: " a message authentication code a digital signature, employ a one-way function (e.g., a cryptographic hash function)"] , a first set of one or more hashed values, [cf. paragraph 0074: II At 606, the base station 120 encrypts a positioning reference signal 160 using the security key 321" paragraph 0080: II the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610, and paragraph 0079: a message authentication code a digital signature, employ a one-way function (e.g., a cryptographic hash function)"] wherein the first set of one or more hashed values is based on one or more hashing operations applied to one or more expected measurement values, wherein the one or more expected measurement values correspond to expected measurements of one or more positioning reference signal (PRS) resources , [cf. paragraph 0074: At 606, the base station 120 encrypts a positioning reference signal 160 using the security key 321" and paragraph 0080: the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610, and paragraph 0079: " a message authentication code a digital signature, employ a one-way function (e.g., a cryptographic hash function)"] of one or more transmission-reception points (TRPs) [cf. figure 6; "Base Station 120" in Wang is the same as the TRP(s) defined in the present application paragraph 0033 as follow: "where the term "base station" refers to a single physical TRP"] measured by a user equipment (UE) during a positioning session [cf. figure 6. relates to a positioning (location determination) session see "step 620" and paragraph 0084: At 620, the UE 110 determines its cellular-network location"] ; and (b) using the first set of one or more hashed values for PRS attack detection [cf. paragraphs 0079-0080: " the UE 110 executes an authentication procedure to determine that the base station 120 is authenticated by the base-station-location server 264. The authentication procedure can be performed in a variety of different ways based on the cryptography employed by the base station at 602, such as those that verify a message authentication code, verify a digital signature, employ a one-way function (e.g., a cryptographic hash function) the UE 110 verifies the digital signal or the MAC using the security key 322." and paragraph 0018: The authenticated base stations use the security keys to generate encrypted positioning reference signals that protect information transmitted to the UE and enable the UE to verify that the base stations are authenticated In this manner, the UE is protected from spoofing attacks that can otherwise cause the UE to provide false or misleading location information to the user.", note that if the digital signature/MAC can not be verified by UE 110 implicitly means that the base station is not authenticated and that it is sending malicious PRS, meaning performing a PRS attack see also paragraph 0043: " the UE 110 determines that the base station 120 is not authenticated and therefore does not use a positioning reference signal 160 transmitted by the unauthenticated base station to determine a cellular- network location."]; and determine whether the one or more actual measurement values of the one or more PRS resources are within acceptable limits of the one or more expected measurement values based on a comparison of a second set of one or more hashed values with the first set of one or more hashed values, wherein the second set of one or more hashed values is based on application of the one or more hashing operations to the one or more actual measurement values (i.e., the UE 110 decrypts the encrypted positioning reference signal 610 to determine the timing information 612 or the processed location 504. The UE 110 generates measurement data for the cellular-network location service based on the decrypted information [0078]-[0079], [0084]). Regarding claim 47, Wang teaches network node, comprising: a memory; at least one transceiver (typical feature of communication device); and at least one processor communicatively coupled to the memory and the at least one transceiver (typical feature of communication device), the at least one processor configured to: receive, from a location server [cf. figure 6: " base station 120", sending "encrypted Positioning Reference Signal (PRS)" in message "608" to "UE 110" and paragraph 0080: II the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610, and paragraph 0079: " a message authentication code a digital signature, employ a one-way function (e.g., a cryptographic hash function)"] , a first set of one or more hashed values, [cf. paragraph 0074: II At 606, the base station 120 encrypts a positioning reference signal 160 using the security key 321" paragraph 0080: II the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610, and paragraph 0079: a message authentication code a digital signature, employ a one-way function (e.g., a cryptographic hash function)"] wherein the first set of one or more hashed values is based on one or more hashing operations applied to one or more expected measurement values, wherein the one or more expected measurement values correspond to expected measurements of one or more positioning reference signal (PRS) resources , [cf. paragraph 0074: At 606, the base station 120 encrypts a positioning reference signal 160 using the security key 321" and paragraph 0080: the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610, and paragraph 0079: " a message authentication code a digital signature, employ a one-way function (e.g., a cryptographic hash function)"] of one or more transmission-reception points (TRPs) [cf. figure 6; "Base Station 120" in Wang is the same as the TRP(s) defined in the present application paragraph 0033 as follow: "where the term "base station" refers to a single physical TRP"] measured by a user equipment (UE) during a positioning session [cf. figure 6. relates to a positioning (location determination) session see "step 620" and paragraph 0084: At 620, the UE 110 determines its cellular-network location"] ; and (b) use the first set of one or more hashed values for PRS attack detection [cf. paragraphs 0079-0080: " the UE 110 executes an authentication procedure to determine that the base station 120 is authenticated by the base-station-location server 264. The authentication procedure can be performed in a variety of different ways based on the cryptography employed by the base station at 602, such as those that verify a message authentication code, verify a digital signature, employ a one-way function (e.g., a cryptographic hash function) the UE 110 verifies the digital signal or the MAC using the security key 322." and paragraph 0018: The authenticated base stations use the security keys to generate encrypted positioning reference signals that protect information transmitted to the UE and enable the UE to verify that the base stations are authenticated In this manner, the UE is protected from spoofing attacks that can otherwise cause the UE to provide false or misleading location information to the user.", note that if the digital signature/MAC can not be verified by UE 110 implicitly means that the base station is not authenticated and that it is sending malicious PRS, meaning performing a PRS attack see also paragraph 0043: " the UE 110 determines that the base station 120 is not authenticated and therefore does not use a positioning reference signal 160 transmitted by the unauthenticated base station to determine a cellular- network location."] Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim 1, 2, 8, 9, 11, 25, 38, and 52 are rejected under 35 U.S.C. 103 as being unpatentable over Wang et al. (US 2020/0322805) in view of 3rd Partnership project, XP052089302. Regarding claim 1, Wang discloses all the features of broadest: A method of wireless communication performed by a network node [cf. figure 6: "UE 110" and paragraph 0074: FIG. 6 illustrates details of example data transactions between the base station 120, the UE 110 for base station location authentication." and paragraph 0010: " FIG. 1 illustrates an example wireless network environment subject to a cellular-network spoofing attack."] comprising: receiving a first set of one or more hashed values, [cf. paragraph 0074: II At 606, the base station 120 encrypts a positioning reference signal 160 using the security key 321" paragraph 0080: II the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610, and paragraph 0079: a message authentication code a digital signature, employ a one-way function (e.g., a cryptographic hash function)"] wherein the first set of one or more hashed values is based on one or more hashing operations applied to one or more expected measurement values of one or more positioning reference signal (PRS) resources , [cf. paragraph 0074: At 606, the base station 120 encrypts a positioning reference signal 160 using the security key 321" and paragraph 0080: the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610, and paragraph 0079: " a message authentication code a digital signature, employ a one-way function (e.g., a cryptographic hash function)"]; measure the one or more PRS resources to obtain one or more actual measurement values [cf. Wang, paragraph 0078: "the UE 110 decrypts the encrypted positioning reference signal 610 to determine the timing information 612 or the processed location 504. The UE 110 generates measurement data for the cellular-network location service based on the decrypted information..."] (d) determining whether the one or more actual measurement values of the one or more PRS resources are within acceptable limits [in Wang the MAC/signature/hash must be equal meaning that "within acceptable limit = equal to"] of the one or more expected measurement values based on a comparison [verification in Wang] of a second set of one or more hashed values [paragraphs 0079-0080: " the UE 110 executes an authentication procedure to determine that the base station 120 is authenticated by the base-station- location server 264. The authentication procedure can be performed in a variety of different ways based on the cryptography verify a message authentication code, verify a digital signature, employ a one-way function (e.g., a cryptographic hash function) the UE 110 verifies the digital signal or the MAC using the security key 322 "] with the first set of one or more hashed values, [paragraph 0080: the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610 " wherein the second set of one or more hashed values is based on application of the one or more hashing operations to the one or more actual measurement values [cf. Wang, paragraphs 0079-0080: " the UE 110 executes an authentication procedure to determine that the base station 120 is authenticated by the base-station-location server 264. The authentication procedure can be performed in a variety of different ways based on the cryptography verify a message authentication code, verify a digital signature, employ a one-way function (e.g., a cryptographic hash function) the UE 110 verifies the digital signal or the MAC using the security key 322 "]. Wang does not explicitly disclose that the MAC/hash of the actual PRS measurement generated by the UE is compared with the MAC/hash of expected PRS measurement generated by TRP/base station, but only that said MAC is generated at UE for TRP/base station MAC verification, however this comparison step is a well known measure for the skilled person from cryptography books and also from the related standard 3rd Partnership project, XP052089302 [cf, related standard D4 figure on page 46 and point 5 and 6: "then calculates the XMAC-I based on KBS as the same that gNB computes MAC-I based on KBS The ME compares XMAC-I with MAC-I. If they are equal, the ME handles the message. Otherwise, the ME marks the cell as high-risk cell in cache "]. Therefore, it would have been obvious to one ordinary skill in the art to combine the disclosure of Wang with the general knowledge relating to MAC/hash verification using "comparison" from cryptography books and also from the related standard 3rd Partnership project, XP052089302 in order to protect location services against spoofing attacks while minimizing battery drain on the UE and reducing network payload overhead. Regarding claim 2, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang further teaches receiving by a "UE 110" a configuration information/list comprising the one or more TRPs (list of authenticated base station) to be used for positioning. Wang does not explicitly mention that the list comprises also the said PRS information however as the UE detects/and uses those values for positioning it is clear for the skilled person that the UE equipment was instructed by said location server to do so even if not explicitly disclosed [cf. Wang, figure 6: step 602 and paragraph 0074: " sends base-station-authentication information 604 to the UE 110. The base- station-authentication information 604 can include the security key 322, the list of authenticated base stations 304, or a combination thereof "]. Regarding claim 8, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang further teaches using hashed values of a particular size L in hinted to by D1, which mentions some hashing algorithms such Chimera TESLA that can have hashes comprising said L number of bits [cf. D1, paragraph 0079: "verify a message authentication code, verify a digital signature, employ a one-way function (e.g., a cryptographic hash function), associated with one or more authentication techniques used in Chimera, one or more authentication techniques used in TESLA, one or more authentication techniques used in SCE, or combinations thereof..."]. Regarding claim 9, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang further teaches using hashed values of a particular size L in hinted to by D1, which mentions some hashing algorithms such Chimera TESLA that can have hashes comprising said L number of bits [cf. D1, paragraph 0079: "verify a message authentication code, verify a digital signature, employ a one-way function (e.g., a cryptographic hash function), associated with one or more authentication techniques used in Chimera, one or more authentication techniques used in TESLA, one or more authentication techniques used in SCE, or combinations thereof..."]. Regarding claim 11, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. The LPP protocol is not explicitly mentioned in Wang but well known, from the related 3GPP [cf. XP052089302, paragraph 0121: "over LTE positioning protocol type A (LPPa" ). Regarding claim 25, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang teaches receiving a second set of one or more hashed values, [cf. paragraph 0074: II At 606, the base station 120 encrypts a positioning reference signal 160 using the security key 321" paragraph 0080: II the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610, and paragraph 0079: a message authentication code a digital signature, employ a one-way function (e.g., a cryptographic hash function)"] wherein the first set of one or more hashed values is based on one or more hashing operations applied to one or more expected measurement values of one or more positioning reference signal (PRS) resources , [cf. paragraph 0074: At 606, the base station 120 encrypts a positioning reference signal 160 using the security key 321" and paragraph 0080: the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610, and paragraph 0079: " a message authentication code a digital signature, employ a one-way function (e.g., a cryptographic hash function)"]; measure the one or more PRS resources to obtain one or more actual measurement values [cf. Wang, paragraph 0078: "the UE 110 decrypts the encrypted positioning reference signal 610 to determine the timing information 612 or the processed location 504. The UE 110 generates measurement data for the cellular-network location service based on the decrypted information..."] (d) determining whether the one or more actual measurement values of the one or more PRS resources are within acceptable limits [in Wang the MAC/signature/hash must be equal meaning that "within acceptable limit = equal to"] of the one or more expected measurement values based on a comparison [verification in Wang] of a second set of one or more hashed values [paragraphs 0079-0080: " the UE 110 executes an authentication procedure to determine that the base station 120 is authenticated by the base-station- location server 264. The authentication procedure can be performed in a variety of different ways based on the cryptography verify a message authentication code, verify a digital signature, employ a one-way function (e.g., a cryptographic hash function) the UE 110 verifies the digital signal or the MAC using the security key 322 "] with the first set of one or more hashed values, [paragraph 0080: the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610 " wherein the second set of one or more hashed values is based on application of the one or more hashing operations to the one or more actual measurement values [cf. Wang, paragraphs 0079-0080: " the UE 110 executes an authentication procedure to determine that the base station 120 is authenticated by the base-station-location server 264. The authentication procedure can be performed in a variety of different ways based on the cryptography verify a message authentication code, verify a digital signature, employ a one-way function (e.g., a cryptographic hash function) the UE 110 verifies the digital signal or the MAC using the security key 322 "]. Wang does not explicitly disclose that the MAC/hash of the actual PRS measurement generated by the UE is compared with the MAC/hash of expected PRS measurement generated by TRP/base station, but only that said MAC is generated at UE for TRP/base station MAC verification, however this comparison step is a well known measure for the skilled person from cryptography books and also from the related standard 3rd Partnership project, XP052089302 [cf, related standard D4 figure on page 46 and point 5 and 6: "then calculates the XMAC-I based on KBS as the same that gNB computes MAC-I based on KBS The ME compares XMAC-I with MAC-I. If they are equal, the ME handles the message. Otherwise, the ME marks the cell as high-risk cell in cache "]. Therefore, it would have been obvious to one ordinary skill in the art to combine the disclosure of Wang with the general knowledge relating to MAC/hash verification using "comparison" from cryptography books and also from the related standard 3rd Partnership project, XP052089302 in order to protect location services against spoofing attacks while minimizing battery drain on the UE and reducing network payload overhead. Regarding claim 38, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. The LPP protocol is not explicitly mentioned in Wang but well known, from the related 3GPP [cf. XP052089302, paragraph 0121: "over LTE positioning protocol type A (LPPa" ). Regarding claim 52, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang teaches receiving a second set of one or more hashed values, [cf. paragraph 0074: II At 606, the base station 120 encrypts a positioning reference signal 160 using the security key 321" paragraph 0080: II the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610, and paragraph 0079: a message authentication code a digital signature, employ a one-way function (e.g., a cryptographic hash function)"] wherein the first set of one or more hashed values is based on one or more hashing operations applied to one or more expected measurement values of one or more positioning reference signal (PRS) resources , [cf. paragraph 0074: At 606, the base station 120 encrypts a positioning reference signal 160 using the security key 321" and paragraph 0080: the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610, and paragraph 0079: " a message authentication code a digital signature, employ a one-way function (e.g., a cryptographic hash function)"]; measure the one or more PRS resources to obtain one or more actual measurement values [cf. Wang, paragraph 0078: "the UE 110 decrypts the encrypted positioning reference signal 610 to determine the timing information 612 or the processed location 504. The UE 110 generates measurement data for the cellular-network location service based on the decrypted information..."] (d) determining whether the one or more actual measurement values of the one or more PRS resources are within acceptable limits [in Wang the MAC/signature/hash must be equal meaning that "within acceptable limit = equal to"] of the one or more expected measurement values based on a comparison [verification in Wang] of a second set of one or more hashed values [paragraphs 0079-0080: " the UE 110 executes an authentication procedure to determine that the base station 120 is authenticated by the base-station- location server 264. The authentication procedure can be performed in a variety of different ways based on the cryptography verify a message authentication code, verify a digital signature, employ a one-way function (e.g., a cryptographic hash function) the UE 110 verifies the digital signal or the MAC using the security key 322 "] with the first set of one or more hashed values, [paragraph 0080: the base station 120 uses the security key 321 to generate a digital signature or a message authentication code (MAC). The digital signature or the MAC is included within the encrypted positioning reference signal 610 " wherein the second set of one or more hashed values is based on application of the one or more hashing operations to the one or more actual measurement values [cf. Wang, paragraphs 0079-0080: " the UE 110 executes an authentication procedure to determine that the base station 120 is authenticated by the base-station-location server 264. The authentication procedure can be performed in a variety of different ways based on the cryptography verify a message authentication code, verify a digital signature, employ a one-way function (e.g., a cryptographic hash function) the UE 110 verifies the digital signal or the MAC using the security key 322 "]. Wang does not explicitly disclose that the MAC/hash of the actual PRS measurement generated by the UE is compared with the MAC/hash of expected PRS measurement generated by TRP/base station, but only that said MAC is generated at UE for TRP/base station MAC verification, however this comparison step is a well known measure for the skilled person from cryptography books and also from the related standard 3rd Partnership project, XP052089302 [cf, related standard D4 figure on page 46 and point 5 and 6: "then calculates the XMAC-I based on KBS as the same that gNB computes MAC-I based on KBS The ME compares XMAC-I with MAC-I. If they are equal, the ME handles the message. Otherwise, the ME marks the cell as high-risk cell in cache "]. Therefore, it would have been obvious to one ordinary skill in the art to combine the disclosure of Wang with the general knowledge relating to MAC/hash verification using "comparison" from cryptography books and also from the related standard 3rd Partnership project, XP052089302 in order to protect location services against spoofing attacks while minimizing battery drain on the UE and reducing network payload overhead. Claims 3-7, 12-18, 21-24, 26-27, 30-36, 39-45, 48-51, and 53-54 are rejected under 35 U.S.C. 103 as being unpatentable over Wang et al. (US 2020/0322805) in view of 3rd Partnership project, XP052089302 further in view of Agarwal et al. (US 2021/185536). Regarding claim 3, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang further teaches detecting attacks based on MAC/hash/ signature values being different from expected MAC/hash/signature (i.e. outside acceptable value/limit) is well known to the skilled person (see for example the passages cited above in XP052089302). Wang does not explicitly mentions that the UE reports errors relating to detection of unauthenticated base stations. However the preceding limitation is known in the art of communication. Agarwal, in the same field, teaches PRS attacks by fake/malicious base stations paragraph 121: upon observing such a cell (i.e., a cell having good signal strength that was not included in the assistance information), the UE may report its observation to the location server and rely on the location server to take further action. If the location server receives such reports from multiple UE's pointing to the same cell as a potential FBS, this can serve to reinforce the FBS hypothesis related to a particular cell. Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have implemented the technique of Agarwal with the combination system of Wang and XP052089302 in order to reduce overhead and save UE energy by simply flagging network anomalies instead of analyzing them. Regarding claim 4, Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal teaches all the limitations above.” Reporting PRS errors/anomaly by a UE to a location server using a bit sequence (e.g. bit map) using flags or using indication about the degree of deviations from expected values” is a well known implementation detail for the skilled person used to exchange error information between a UE and wireless network nodes. Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 4 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 5, Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal teaches all the limitations above.” Reporting PRS errors/anomaly by a UE to a location server using a bit sequence (e.g. bit map) using flags or using indication about the degree of deviations from expected values” is a well known implementation detail for the skilled person used to exchange error information between a UE and wireless network nodes. Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 5 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 6, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Agarwal further teaches PRS value relating to RSRP, RSTD, AoA, AoD, ZoA, ZoD etc are well known from related standard wherein NR supports a number of cellular network-based positioning technologies, including downlink-based, uplink-based, and downlink-and-uplink-based positioning methods. Downlink-based positioning methods include observed time difference of arrival (OTDOA) in LTE, downlink time difference of arrival (DL-TDOA) in NR, and downlink angle-of-departure (DL-AoD) in NR. In an OTDOA or DL-TDOA positioning procedure, a UE measures the differences between the times of arrival (ToAs) of reference signals (e.g., PRS, TRS, CSI-RS, SSB, etc.) received from pairs of base stations, referred to as reference signal time difference (RSTD) or time difference of arrival (TDOA) measurements, and reports them to a positioning entity [0093] and [0095]). Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 7 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 7, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Agarwal further teaches PRS value relating to RSRP, RSTD, AoA, AoD, ZoA, ZoD etc are well known from related standard wherein NR supports a number of cellular network-based positioning technologies, including downlink-based, uplink-based, and downlink-and-uplink-based positioning methods. Downlink-based positioning methods include observed time difference of arrival (OTDOA) in LTE, downlink time difference of arrival (DL-TDOA) in NR, and downlink angle-of-departure (DL-AoD) in NR. In an OTDOA or DL-TDOA positioning procedure, a UE measures the differences between the times of arrival (ToAs) of reference signals (e.g., PRS, TRS, CSI-RS, SSB, etc.) received from pairs of base stations, referred to as reference signal time difference (RSTD) or time difference of arrival (TDOA) measurements, and reports them to a positioning entity [0093] and [0095]). Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 7 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 12, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. They do not explicitly discloses the network node is a base station; the one or more PRS resources are uplink PRS (UL-PRS) resources; and the second set of one or more hashed values are received from a user equipment (UE). However, the preceding limitation is known in the art of communications. Agarwall a UE may use a particular receive beam to receive one or more reference downlink reference signals (e.g., positioning reference signals (PRS), tracking reference signals (TRS), phase tracking reference signal (PTRS), cell-specific reference signals (CRS), channel state information reference signals (CSI-RS), primary synchronization signals (PSS), secondary synchronization signals (SSS), synchronization signal blocks (SSBs), etc.) from a base station. The UE can then form a transmit beam for sending one or more uplink reference signals (e.g., uplink positioning reference signals (UL-PRS), sounding reference signal (SRS), demodulation reference signals (DMRS), PTRS, etc.) to that base station based on the parameters of the receive beam… if a base station is forming the downlink beam to transmit a reference signal to a UE, the downlink beam is a transmit beam. If the UE is forming the downlink beam, however, it is a receive beam to receive the downlink reference signal. Similarly, an “uplink” beam may be either a transmit beam or a receive beam, depending on the entity forming it ([0040]-[0042]). Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have implemented the technique of Agarwal with the combination system of Wang and XP052089302 in order to reduce overhead and save UE energy by simply flagging network anomalies instead of analyzing them. Regarding claim 13, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang teaches and the first set of one or more hashed values is received from a base station (i.e., in performing UE authentication procedure to verify digital signature (e.g, Cryptographic hash function ([0079]). They do not explicitly discloses the network node is a user equipment (UE); the one or more PRS resources are downlink link PRS (DL-PRS) resources. However, the preceding limitation is known in the art of communications. Agarwall a UE may use a particular receive beam to receive one or more reference downlink reference signals (e.g., positioning reference signals (PRS), tracking reference signals (TRS), phase tracking reference signal (PTRS), cell-specific reference signals (CRS), channel state information reference signals (CSI-RS), primary synchronization signals (PSS), secondary synchronization signals (SSS), synchronization signal blocks (SSBs), etc.) from a base station. The UE can then form a transmit beam for sending one or more uplink reference signals (e.g., uplink positioning reference signals (UL-PRS), sounding reference signal (SRS), demodulation reference signals (DMRS), PTRS, etc.) to that base station based on the parameters of the receive beam ([0040]-[0042]). Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have implemented the technique of Agarwal with the combination system of Wang and XP052089302 in order to reduce overhead and save UE energy by simply flagging network anomalies instead of analyzing them. Regarding claim 14, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. They do not explicitly discloses wherein: the network node is a first user equipment (UE); the first set of one or more hashed values are received from a second UE; and the one or more PRS resources are sidelink PRS (SL-PRS) resources. However, the preceding limitation is known in the art of communications. Agarwall a UE may use a particular receive beam to receive one or more reference downlink reference signals (e.g., positioning reference signals (PRS), tracking reference signals (TRS), phase tracking reference signal (PTRS), cell-specific reference signals (CRS), channel state information reference signals (CSI-RS), primary synchronization signals (PSS), secondary synchronization signals (SSS), synchronization signal blocks (SSBs), etc.) from a base station. The UE can then form a transmit beam for sending one or more uplink reference signals (e.g., uplink positioning reference signals (UL-PRS), sounding reference signal (SRS), demodulation reference signals (DMRS), PTRS, etc.) to that base station based on the parameters of the receive beam… if a base station is forming the downlink beam to transmit a reference signal to a UE, the downlink beam is a transmit beam. If the UE is forming the downlink beam, however, it is a receive beam to receive the downlink reference signal. Similarly, an “uplink” beam may be either a transmit beam or a receive beam, depending on the entity forming it ([0040]-[0042], [0045], see also fig. 1). Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have implemented the technique of Agarwal with the combination system of Wang and XP052089302 in order to reduce overhead and save UE energy by simply flagging network anomalies instead of analyzing them. Regarding claim 15, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang does not explicitly discloses carrying PRS in a RRC, e.g. PDSCH or PSSCH but those are well known that can be implemented in the combination of Wang and XP05208930 by a skilled person using the disclosure of Agarwal, wherein the FBS then broadcasts an SSB (possibly with a different PCI) and a PDCCH/PDSCH carrying the same SI. A UE in an RRC_IDLE or RRC_INACTIVE state in the vicinity of the FBS may measure good SSB signal strength from the FBS and camp on the FBS after reading the SI. The UE would then not receive mobile-terminated (MT) or emergency calls and remain unaware of the existence of the FBS until the UE initiates signaling on the uplink and does not receive a (integrity protected) response. In this way, the FBS may successfully launch a denial-of-service (DOS) attack and remain undetected for a substantial amount of time [0113]-[0115]. Note that usage of MAC-CE field of PDSCH or PSSCH to insert hash values is obvious design/implementation option for the skilled person. Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have implemented the technique of Agarwal with the combination system of Wang and XP052089302 in order to reduce overhead and save UE energy by simply flagging network anomalies instead of analyzing them. Regarding claim 16, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang does not explicitly discloses carrying PRS in a RRC, e.g. PDSCH or PSSCH but those are well known that can be implemented in the combination of Wang and XP05208930 by a skilled person using the disclosure of Agarwal, wherein the FBS then broadcasts an SSB (possibly with a different PCI) and a PDCCH/PDSCH carrying the same SI. A UE in an RRC_IDLE or RRC_INACTIVE state in the vicinity of the FBS may measure good SSB signal strength from the FBS and camp on the FBS after reading the SI. The UE would then not receive mobile-terminated (MT) or emergency calls and remain unaware of the existence of the FBS until the UE initiates signaling on the uplink and does not receive a (integrity protected) response. In this way, the FBS may successfully launch a denial-of-service (DOS) attack and remain undetected for a substantial amount of time [0113]-[0115]. Note that usage of MAC-CE field of PDSCH or PSSCH to insert hash values is obvious design/implementation option for the skilled person. Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have implemented the technique of Agarwal with the combination system of Wang and XP052089302 in order to reduce overhead and save UE energy by simply flagging network anomalies instead of analyzing them. Regarding claim 17, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang does not explicitly discloses carrying PRS in a RRC, e.g. PDSCH or PSSCH but those are well known that can be implemented in the combination of Wang and XP05208930 by a skilled person using the disclosure of Agarwal, wherein the FBS then broadcasts an SSB (possibly with a different PCI) and a PDCCH/PDSCH carrying the same SI. A UE in an RRC_IDLE or RRC_INACTIVE state in the vicinity of the FBS may measure good SSB signal strength from the FBS and camp on the FBS after reading the SI. The UE would then not receive mobile-terminated (MT) or emergency calls and remain unaware of the existence of the FBS until the UE initiates signaling on the uplink and does not receive a (integrity protected) response. In this way, the FBS may successfully launch a denial-of-service (DOS) attack and remain undetected for a substantial amount of time [0113]-[0115]. Note that usage of MAC-CE field of PDSCH or PSSCH to insert hash values is obvious design/implementation option for the skilled person. Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have implemented the technique of Agarwal with the combination system of Wang and XP052089302 in order to reduce overhead and save UE energy by simply flagging network anomalies instead of analyzing them. Regarding claim 18, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. does not explicitly discloses carrying PRS in a RRC, e.g. PDSCH or PSSCH but those are well known implementation options to the skilled person [cf. from Agarwal, paragraph 0114]. Note that usage of MAC-CE field of PDSCH or PSSCH to insert hash values is obvious design/implementation option for the skilled person. Regarding claim 21, Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal teaches all the limitations above.” Reporting PRS errors/anomaly by a UE to a location server using a bit sequence (e.g. bit map) using flags or using indication about the degree of deviations from expected values” is a well known implementation detail for the skilled person used to exchange error information between a UE and wireless network nodes. Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 4 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 22, Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal teaches all the limitations above.” Reporting PRS errors/anomaly by a UE to a location server using a bit sequence (e.g. bit map) using flags or using indication about the degree of deviations from expected values” is a well known implementation detail for the skilled person used to exchange error information between a UE and wireless network nodes. Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 4 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 23, Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal teaches all the limitations above.” Reporting PRS errors/anomaly by a UE to a location server using a bit sequence (e.g. bit map) using flags or using indication about the degree of deviations from expected values” is a well known implementation detail for the skilled person used to exchange error information between a UE and wireless network nodes. Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 4 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 24, Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal teaches all the limitations above.” Reporting PRS errors/anomaly by a UE to a location server using a bit sequence (e.g. bit map) using flags or using indication about the degree of deviations from expected values” is a well known implementation detail for the skilled person used to exchange error information between a UE and wireless network nodes. Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 4 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 26, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Agarwal further teaches PRS value relating to RSRP, RSTD, AoA, AoD, ZoA, ZoD etc are well known from related standard wherein NR supports a number of cellular network-based positioning technologies, including downlink-based, uplink-based, and downlink-and-uplink-based positioning methods. Downlink-based positioning methods include observed time difference of arrival (OTDOA) in LTE, downlink time difference of arrival (DL-TDOA) in NR, and downlink angle-of-departure (DL-AoD) in NR. In an OTDOA or DL-TDOA positioning procedure, a UE measures the differences between the times of arrival (ToAs) of reference signals (e.g., PRS, TRS, CSI-RS, SSB, etc.) received from pairs of base stations, referred to as reference signal time difference (RSTD) or time difference of arrival (TDOA) measurements, and reports them to a positioning entity [0093] and [0095]). Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 7 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 27, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Agarwal further teaches PRS value relating to RSRP, RSTD, AoA, AoD, ZoA, ZoD etc are well known from related standard wherein NR supports a number of cellular network-based positioning technologies, including downlink-based, uplink-based, and downlink-and-uplink-based positioning methods. Downlink-based positioning methods include observed time difference of arrival (OTDOA) in LTE, downlink time difference of arrival (DL-TDOA) in NR, and downlink angle-of-departure (DL-AoD) in NR. In an OTDOA or DL-TDOA positioning procedure, a UE measures the differences between the times of arrival (ToAs) of reference signals (e.g., PRS, TRS, CSI-RS, SSB, etc.) received from pairs of base stations, referred to as reference signal time difference (RSTD) or time difference of arrival (TDOA) measurements, and reports them to a positioning entity [0093] and [0095]). Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 7 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 30, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang further teaches detecting attacks based on MAC/hash/ signature values being different from expected MAC/hash/signature (i.e. outside acceptable value/limit) is well known to the skilled person (see for example the passages cited above in XP052089302). Wang does not explicitly mentions that the UE reports errors relating to detection of unauthenticated base stations. However the preceding limitation is known in the art of communication. Agarwal, in the same field, teaches PRS attacks by fake/malicious base stations paragraph 121: upon observing such a cell (i.e., a cell having good signal strength that was not included in the assistance information), the UE may report its observation to the location server and rely on the location server to take further action. If the location server receives such reports from multiple UE's pointing to the same cell as a potential FBS, this can serve to reinforce the FBS hypothesis related to a particular cell. Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have implemented the technique of Agarwal with the combination system of Wang and XP052089302 in order to reduce overhead and save UE energy by simply flagging network anomalies instead of analyzing them. Regarding claim 31, Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal teaches all the limitations above.” Reporting PRS errors/anomaly by a UE to a location server using a bit sequence (e.g. bit map) using flags or using indication about the degree of deviations from expected values” is a well known implementation detail for the skilled person used to exchange error information between a UE and wireless network nodes. Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 4 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 32, Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal teaches all the limitations above.” Reporting PRS errors/anomaly by a UE to a location server using a bit sequence (e.g. bit map) using flags or using indication about the degree of deviations from expected values” is a well known implementation detail for the skilled person used to exchange error information between a UE and wireless network nodes. Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 4 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 33, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Agarwal further teaches PRS value relating to RSRP, RSTD, AoA, AoD, ZoA, ZoD etc are well known from related standard wherein NR supports a number of cellular network-based positioning technologies, including downlink-based, uplink-based, and downlink-and-uplink-based positioning methods. Downlink-based positioning methods include observed time difference of arrival (OTDOA) in LTE, downlink time difference of arrival (DL-TDOA) in NR, and downlink angle-of-departure (DL-AoD) in NR. In an OTDOA or DL-TDOA positioning procedure, a UE measures the differences between the times of arrival (ToAs) of reference signals (e.g., PRS, TRS, CSI-RS, SSB, etc.) received from pairs of base stations, referred to as reference signal time difference (RSTD) or time difference of arrival (TDOA) measurements, and reports them to a positioning entity [0093] and [0095]). Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 7 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 34, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Agarwal further teaches PRS value relating to RSRP, RSTD, AoA, AoD, ZoA, ZoD etc are well known from related standard wherein NR supports a number of cellular network-based positioning technologies, including downlink-based, uplink-based, and downlink-and-uplink-based positioning methods. Downlink-based positioning methods include observed time difference of arrival (OTDOA) in LTE, downlink time difference of arrival (DL-TDOA) in NR, and downlink angle-of-departure (DL-AoD) in NR. In an OTDOA or DL-TDOA positioning procedure, a UE measures the differences between the times of arrival (ToAs) of reference signals (e.g., PRS, TRS, CSI-RS, SSB, etc.) received from pairs of base stations, referred to as reference signal time difference (RSTD) or time difference of arrival (TDOA) measurements, and reports them to a positioning entity [0093] and [0095]). Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 7 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 35, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang further teaches using hashed values of a particular size L in hinted to by D1, which mentions some hashing algorithms such Chimera TESLA that can have hashes comprising said L number of bits [cf. D1, paragraph 0079: "verify a message authentication code, verify a digital signature, employ a one-way function (e.g., a cryptographic hash function), associated with one or more authentication techniques used in Chimera, one or more authentication techniques used in TESLA, one or more authentication techniques used in SCE, or combinations thereof..."]. Regarding claim 36, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang further teaches using hashed values of a particular size L in hinted to by D1, which mentions some hashing algorithms such Chimera TESLA that can have hashes comprising said L number of bits [cf. D1, paragraph 0079: "verify a message authentication code, verify a digital signature, employ a one-way function (e.g., a cryptographic hash function), associated with one or more authentication techniques used in Chimera, one or more authentication techniques used in TESLA, one or more authentication techniques used in SCE, or combinations thereof..."]. Regarding claim 39, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. They do not explicitly discloses the network node is a base station; the one or more PRS resources are uplink PRS (UL-PRS) resources; and the second set of one or more hashed values are received from a user equipment (UE). However, the preceding limitation is known in the art of communications. Agarwall a UE may use a particular receive beam to receive one or more reference downlink reference signals (e.g., positioning reference signals (PRS), tracking reference signals (TRS), phase tracking reference signal (PTRS), cell-specific reference signals (CRS), channel state information reference signals (CSI-RS), primary synchronization signals (PSS), secondary synchronization signals (SSS), synchronization signal blocks (SSBs), etc.) from a base station. The UE can then form a transmit beam for sending one or more uplink reference signals (e.g., uplink positioning reference signals (UL-PRS), sounding reference signal (SRS), demodulation reference signals (DMRS), PTRS, etc.) to that base station based on the parameters of the receive beam… if a base station is forming the downlink beam to transmit a reference signal to a UE, the downlink beam is a transmit beam. If the UE is forming the downlink beam, however, it is a receive beam to receive the downlink reference signal. Similarly, an “uplink” beam may be either a transmit beam or a receive beam, depending on the entity forming it ([0040]-[0042]). Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have implemented the technique of Agarwal with the combination system of Wang and XP052089302 in order to reduce overhead and save UE energy by simply flagging network anomalies instead of analyzing them. Regarding claim 40, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang teaches and the first set of one or more hashed values is received from a base station (i.e., in performing UE authentication procedure to verify digital signature (e.g, Cryptographic hash function ([0079]). They do not explicitly discloses the network node is a user equipment (UE); the one or more PRS resources are downlink link PRS (DL-PRS) resources. However, the preceding limitation is known in the art of communications. Agarwall a UE may use a particular receive beam to receive one or more reference downlink reference signals (e.g., positioning reference signals (PRS), tracking reference signals (TRS), phase tracking reference signal (PTRS), cell-specific reference signals (CRS), channel state information reference signals (CSI-RS), primary synchronization signals (PSS), secondary synchronization signals (SSS), synchronization signal blocks (SSBs), etc.) from a base station. The UE can then form a transmit beam for sending one or more uplink reference signals (e.g., uplink positioning reference signals (UL-PRS), sounding reference signal (SRS), demodulation reference signals (DMRS), PTRS, etc.) to that base station based on the parameters of the receive beam ([0040]-[0042]). Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have implemented the technique of Agarwal with the combination system of Wang and XP052089302 in order to reduce overhead and save UE energy by simply flagging network anomalies instead of analyzing them. Regarding claim 41, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. They do not explicitly discloses wherein: the network node is a first user equipment (UE); the first set of one or more hashed values are received from a second UE; and the one or more PRS resources are sidelink PRS (SL-PRS) resources. However, the preceding limitation is known in the art of communications. Agarwall a UE may use a particular receive beam to receive one or more reference downlink reference signals (e.g., positioning reference signals (PRS), tracking reference signals (TRS), phase tracking reference signal (PTRS), cell-specific reference signals (CRS), channel state information reference signals (CSI-RS), primary synchronization signals (PSS), secondary synchronization signals (SSS), synchronization signal blocks (SSBs), etc.) from a base station. The UE can then form a transmit beam for sending one or more uplink reference signals (e.g., uplink positioning reference signals (UL-PRS), sounding reference signal (SRS), demodulation reference signals (DMRS), PTRS, etc.) to that base station based on the parameters of the receive beam… if a base station is forming the downlink beam to transmit a reference signal to a UE, the downlink beam is a transmit beam. If the UE is forming the downlink beam, however, it is a receive beam to receive the downlink reference signal. Similarly, an “uplink” beam may be either a transmit beam or a receive beam, depending on the entity forming it ([0040]-[0042], [0045], see also fig. 1). Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have implemented the technique of Agarwal with the combination system of Wang and XP052089302 in order to reduce overhead and save UE energy by simply flagging network anomalies instead of analyzing them. Regarding claim 42, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang does not explicitly discloses carrying PRS in a RRC, e.g. PDSCH or PSSCH but those are well known that can be implemented in the combination of Wang and XP05208930 by a skilled person using the disclosure of Agarwal, wherein the FBS then broadcasts an SSB (possibly with a different PCI) and a PDCCH/PDSCH carrying the same SI. A UE in an RRC_IDLE or RRC_INACTIVE state in the vicinity of the FBS may measure good SSB signal strength from the FBS and camp on the FBS after reading the SI. The UE would then not receive mobile-terminated (MT) or emergency calls and remain unaware of the existence of the FBS until the UE initiates signaling on the uplink and does not receive a (integrity protected) response. In this way, the FBS may successfully launch a denial-of-service (DOS) attack and remain undetected for a substantial amount of time [0113]-[0115]. Note that usage of MAC-CE field of PDSCH or PSSCH to insert hash values is obvious design/implementation option for the skilled person. Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have implemented the technique of Agarwal with the combination system of Wang and XP052089302 in order to reduce overhead and save UE energy by simply flagging network anomalies instead of analyzing them. Regarding claim 43, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang does not explicitly discloses carrying PRS in a RRC, e.g. PDSCH or PSSCH but those are well known that can be implemented in the combination of Wang and XP05208930 by a skilled person using the disclosure of Agarwal, wherein the FBS then broadcasts an SSB (possibly with a different PCI) and a PDCCH/PDSCH carrying the same SI. A UE in an RRC_IDLE or RRC_INACTIVE state in the vicinity of the FBS may measure good SSB signal strength from the FBS and camp on the FBS after reading the SI. The UE would then not receive mobile-terminated (MT) or emergency calls and remain unaware of the existence of the FBS until the UE initiates signaling on the uplink and does not receive a (integrity protected) response. In this way, the FBS may successfully launch a denial-of-service (DOS) attack and remain undetected for a substantial amount of time [0113]-[0115]. Note that usage of MAC-CE field of PDSCH or PSSCH to insert hash values is obvious design/implementation option for the skilled person. Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have implemented the technique of Agarwal with the combination system of Wang and XP052089302 in order to reduce overhead and save UE energy by simply flagging network anomalies instead of analyzing them. Regarding claim 44, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Wang does not explicitly discloses carrying PRS in a RRC, e.g. PDSCH or PSSCH but those are well known that can be implemented in the combination of Wang and XP05208930 by a skilled person using the disclosure of Agarwal, wherein the FBS then broadcasts an SSB (possibly with a different PCI) and a PDCCH/PDSCH carrying the same SI. A UE in an RRC_IDLE or RRC_INACTIVE state in the vicinity of the FBS may measure good SSB signal strength from the FBS and camp on the FBS after reading the SI. The UE would then not receive mobile-terminated (MT) or emergency calls and remain unaware of the existence of the FBS until the UE initiates signaling on the uplink and does not receive a (integrity protected) response. In this way, the FBS may successfully launch a denial-of-service (DOS) attack and remain undetected for a substantial amount of time [0113]-[0115]. Note that usage of MAC-CE field of PDSCH or PSSCH to insert hash values is obvious design/implementation option for the skilled person. Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have implemented the technique of Agarwal with the combination system of Wang and XP052089302 in order to reduce overhead and save UE energy by simply flagging network anomalies instead of analyzing them. Regarding claim 45, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. does not explicitly discloses carrying PRS in a RRC, e.g. PDSCH or PSSCH but those are well known implementation options to the skilled person [cf. from Agarwal, paragraph 0114]. Note that usage of MAC-CE field of PDSCH or PSSCH to insert hash values is obvious design/implementation option for the skilled person. Regarding claim 48, Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal teaches all the limitations above.” Reporting PRS errors/anomaly by a UE to a location server using a bit sequence (e.g. bit map) using flags or using indication about the degree of deviations from expected values” is a well known implementation detail for the skilled person used to exchange error information between a UE and wireless network nodes. Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 4 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 49, Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal teaches all the limitations above.” Reporting PRS errors/anomaly by a UE to a location server using a bit sequence (e.g. bit map) using flags or using indication about the degree of deviations from expected values” is a well known implementation detail for the skilled person used to exchange error information between a UE and wireless network nodes. Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 4 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 50, Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal teaches all the limitations above.” Reporting PRS errors/anomaly by a UE to a location server using a bit sequence (e.g. bit map) using flags or using indication about the degree of deviations from expected values” is a well known implementation detail for the skilled person used to exchange error information between a UE and wireless network nodes. Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 4 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 51, Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal teaches all the limitations above.” Reporting PRS errors/anomaly by a UE to a location server using a bit sequence (e.g. bit map) using flags or using indication about the degree of deviations from expected values” is a well known implementation detail for the skilled person used to exchange error information between a UE and wireless network nodes. Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 4 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 53, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Agarwal further teaches PRS value relating to RSRP, RSTD, AoA, AoD, ZoA, ZoD etc are well known from related standard wherein NR supports a number of cellular network-based positioning technologies, including downlink-based, uplink-based, and downlink-and-uplink-based positioning methods. Downlink-based positioning methods include observed time difference of arrival (OTDOA) in LTE, downlink time difference of arrival (DL-TDOA) in NR, and downlink angle-of-departure (DL-AoD) in NR. In an OTDOA or DL-TDOA positioning procedure, a UE measures the differences between the times of arrival (ToAs) of reference signals (e.g., PRS, TRS, CSI-RS, SSB, etc.) received from pairs of base stations, referred to as reference signal time difference (RSTD) or time difference of arrival (TDOA) measurements, and reports them to a positioning entity [0093] and [0095]). Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 7 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Regarding claim 54, Wang in view of 3rd Partnership project, XP052089302 teaches all the limitations above. Agarwal further teaches PRS value relating to RSRP, RSTD, AoA, AoD, ZoA, ZoD etc are well known from related standard wherein NR supports a number of cellular network-based positioning technologies, including downlink-based, uplink-based, and downlink-and-uplink-based positioning methods. Downlink-based positioning methods include observed time difference of arrival (OTDOA) in LTE, downlink time difference of arrival (DL-TDOA) in NR, and downlink angle-of-departure (DL-AoD) in NR. In an OTDOA or DL-TDOA positioning procedure, a UE measures the differences between the times of arrival (ToAs) of reference signals (e.g., PRS, TRS, CSI-RS, SSB, etc.) received from pairs of base stations, referred to as reference signal time difference (RSTD) or time difference of arrival (TDOA) measurements, and reports them to a positioning entity [0093] and [0095]). Accordingly, one of ordinary skill in the art, could have easily conceived the invention in claim 7 from a combination of Wang in view of 3rd Partnership project, XP052089302 further in view of Agarwal. Claims 19, 46 are rejected under 35 U.S.C. 103 as being unpatentable over Wang et al. (US 2020/0322805) in view of 3rd Partnership project, XP052089302 further in view of Lee et al. (US 2020/0344605). Regarding claim 19, Wang in view of XP052089302) teaches all the limitations above. “executing an assignment operation to assign one or more hashed values of the second set of hashed values to a set of hashed bins, wherein the set of hashed bins are based on the first set of hashed values; and reporting information relating to one or more hashed values of the second set of hashed values that are not assignable to an allowed hashed bin of the set of hashed bins” could have been derived by one of ordinary skill in the art from Lee’s reference, which discloses that the UE may receive system information from a base station and may calculate a hash value using the system information as input to a hashing function. Similarly, prior to transmitting the system information, a valid base station may calculate a hash value using the system information as input to a hashing function. The base station may transmit the calculated hash value (e.g., which may represent or be included in a set of hash values) to the UE in an AS SMC message. In some cases, the base station may calculate a hash value for a limited set of system information (e.g., essential SIBs, such as MIB and SIB1/2), as the base station may not know which SIB the UE is to read. The UE may determine whether the received system information was modified based on the hash value. In cases where the UE indicates a mismatch of hash information (e.g., in cases where the UE indicates, via an AS security mode complete message, that system information may have been modified or corrupted), the base station may re-transmit the system information (e.g., in an integrity protected RRC reconfiguration message) ([0048]-[0049], [0091]). Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have integrated the hash-based verification disclosure of Lee within the system of Wang and XP052089302 in order to provide a lightweight, robust security mechanism to prevent false base station attacks and detect corrupted or spoofed system information (SI) without burdening the network with continuous overhead. Regarding claim 19, Wang in view of XP052089302) teaches all the limitations above. “executing an assignment operation to assign one or more hashed values of the second set of hashed values to a set of hashed bins, wherein the set of hashed bins are based on the first set of hashed values; and reporting information relating to one or more hashed values of the second set of hashed values that are not assignable to an allowed hashed bin of the set of hashed bins” could have been derived by one of ordinary skill in the art from Lee’s reference, which discloses that the UE may receive system information from a base station and may calculate a hash value using the system information as input to a hashing function. Similarly, prior to transmitting the system information, a valid base station may calculate a hash value using the system information as input to a hashing function. The base station may transmit the calculated hash value (e.g., which may represent or be included in a set of hash values) to the UE in an AS SMC message. In some cases, the base station may calculate a hash value for a limited set of system information (e.g., essential SIBs, such as MIB and SIB1/2), as the base station may not know which SIB the UE is to read. The UE may determine whether the received system information was modified based on the hash value. In cases where the UE indicates a mismatch of hash information (e.g., in cases where the UE indicates, via an AS security mode complete message, that system information may have been modified or corrupted), the base station may re-transmit the system information (e.g., in an integrity protected RRC reconfiguration message) ([0048]-[0049], [0091]). Therefore, it would have been obvious to one of ordinary skill in the art, at the time of the invention, to have integrated the hash-based verification disclosure of Lee within the system of Wang and XP052089302 in order to provide a lightweight, robust security mechanism to prevent false base station attacks and detect corrupted or spoofed system information (SI) without burdening the network with continuous overhead. Allowable Subject Matter Claims 10 and 37 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to JEAN ALLAND GELIN whose telephone number is (571)272-7842. The examiner can normally be reached MON-FR 9-6 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JINSONG HU can be reached at 571-272-3965. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JEAN A GELIN/Primary Examiner, Art Unit 2643
Read full office action

Prosecution Timeline

Sep 13, 2024
Application Filed
Jul 21, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750906
Access During Small Data Transmission
3y 7m to grant Granted Sep 29, 2026
Patent 12750909
Method for Handling a Mobility Management State Transition After Fallback to RRC Establishment
2y 4m to grant Granted Sep 29, 2026
Patent 12739671
Segmented Communication Over Wireless Networks
3y 0m to grant Granted Sep 15, 2026
Patent 12733026
SENSING SIGNAL TRANSMISSION METHOD AND APPARATUS
3y 4m to grant Granted Sep 08, 2026
Patent 12732870
ADAPTIVE SPECTRUM CONTROL
2y 9m to grant Granted Sep 08, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
88%
Grant Probability
93%
With Interview (+4.5%)
2y 3m (~3m remaining)
Median Time to Grant
Low
PTA Risk
Based on 1273 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month